Efficient Trust Negotiation based on Trust Evaluations and Adaptive Policies
نویسنده
چکیده
Automated trust negotiation (ATN) is an approach that establishes mutual trust between strangers wishing to share resources or conduct business by gradually requesting and disclosing digitally signed credentials. Previous work on improving negotiation efficiency mainly focuses on using history negotiation information, which may lead to unnecessary information leakage and cannot improve the negotiation efficiency when both negotiators do not have appropriate history information. Thus in this paper, we enhance the negotiation efficiency from a new aspect, that is, adjust policies based on trust evaluations. An ATN framework is designed to enhance the negotiation efficiency. This framework can simplify the negotiation process, reduce the number of exchanged credentials and credential validations whenever possible. Furthermore, it avoids revealing unnecessary information during negotiations. This framework presents a number of innovative features, such as the support of virtual organizations and trust evaluations, and the use of fine-grained adaptive policies to adjust policies based on the trustworthiness levels. Finally, we report experimental results based on our implementation of this framework, which show that our framework can greatly enhance the negotiation efficiency whenever possible. Index Term—automated trust negotiation, access control policy, trustworthiness level, trust evaluation, efficiency
منابع مشابه
A Requirements-Driven Trust Framework for Secure Interoperation in Open Environments
A key challenge in emerging multi-domain open environments is the need to establish trust-based, loosely coupled partnerships between previously unknown domains. An efficient trust framework is essential to facilitate trust negotiation based on the service requirements of the partner domains. While several trust mechanisms have been proposed, none address the issue of integrating the trust mech...
متن کاملTrust-Serv: A Lightweight Trust Negotiation Service
In Web service environments, scalable access control methods are required, as requester populations are often large and dynamic. For this reason, requester identities are often not known in advance, and traditional access control models that rely on identity to determine access do not fit. Other models require requesters to submit credentials (i.e., signed assertions describing attributes of th...
متن کاملPrevious and Ongoing Work
Broadly speaking, my research interests lie at the intersection of the computer security, privacy, and distributed systems disciplines. In particular, I am interested in systems that facilitate secure interactions across multiple security domains while still preserving each individual’s privacy and autonomy. For my dissertation, I have focused mainly on the systems challenges surrounding the ad...
متن کاملHiTrust: building cross-organizational trust relationship based on a hybrid negotiation tree
In a pervasive computing environment, the need to establish trust amongst distributed services has attracted increasing attentions from both the industry and academia. As a widely adopted solution to carry a principal’s identity and attributes of different organizations, the credential-based trust establishment has become popular over Internet. In this paper, we propose a hybrid negotiation tre...
متن کاملA Unified Scheme for Resource Protection in Automated Trust Negotiation
Automated trust negotiation is an approach to establishing trust between strangers through iterative disclosure of digital credentials. In automated trust negotiation, access control policies play a key role in protecting resources from unauthorized access. Unlike in traditional trust management systems, the access control policy for a resource is usually unknown to the party requesting access ...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید
ثبت ناماگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید
ورودعنوان ژورنال:
- JCP
دوره 6 شماره
صفحات -
تاریخ انتشار 2011